Zweite Schicht DE, Deutsche Fassung Book a call

Use case

Updated

From the first outage to the final report to BaFin: a workflow that keeps both clocks of the DORA reporting duty for ICT incidents.

A payment institution with around 180 employees processes payments for merchants; its contract system runs at a data centre service provider. Monday, 07:05: the contract system is not responding. On the phone, the service provider talks of a storage failure, there is no estimate of when it will be back, and the day's direct debits cannot be generated. From now on two clocks are running: 24 hours from becoming aware, and an additional four hours once the incident has been classified as major. Anyone who puts off the classification until all the figures are in loses the time needed for the notification. We supply the software your team uses to work through both clocks. Classification and notification stay with your people; legal advice is not part of what we do.

Sketch of a half-open vault door in a wall with a combination dial and a lever, in front of it a table with a telephone and a form tray, on the wall a clock showing four.

Duty

What the law requires

The Digital Operational Resilience Act (DORA) has applied since 17 January 2025 to banks, payment and e-money institutions, insurers, asset management companies and other financial entities, and to the IT service providers that work for them. Leasing and factoring institutions are not named in the regulation itself; in Germany the requirements apply to them via Section 1a(2a) of the German Banking Act (KWG), in simplified form and with a transition period until 1 January 2027.

Reporting duties for major ICT-related incidents under Article 19 DORA
Legal basisRegulation (EU) 2022/2554 (DORA), Article 19; deadlines under Delegated Regulation (EU) 2025/301; classification under Delegated Regulation (EU) 2024/1772
Who is affectedFinancial entities: credit institutions, payment and e-money institutions, investment firms, insurers, asset management companies and others, plus their critical information and communication technology (ICT) third-party service providers. Financial leasing and factoring institutions only via Section 1a(2a) KWG, simplified and with a transition period until 1 January 2027.
TriggerAn ICT-related incident classified as major under the criteria of the Delegated Regulation: clients affected, duration, geographical spread, data losses, criticality of the services affected, costs
DeadlinesInitial notification no later than 4 hours after classification as major and no later than 24 hours after becoming aware, intermediate report within 72 hours of the initial notification, final report one month after the last intermediate report
Recipient and channelIn Germany, the Federal Financial Supervisory Authority (BaFin) via its reporting portal
Client informationClients must be informed without undue delay if the incident affects their financial interests (Article 19(3)), including the measures the entity is taking
Service providersIf the incident occurs at the ICT third-party service provider, the reporting duty stays with the financial entity. When the service provider has to inform its customer is set out in the contract.
Legal position as ofOctober 2026. We build the workflow; the legal assessment of whether an incident is major stays with your legal department, compliance team or law firm.

Clock

The workflow, hour by hour

What sets DORA apart is the double clock. The 24 hours run from becoming aware, the four hours from classification, and whichever ends first applies. That is why the tool collects the criteria from the very first moment instead of waiting for a complete report.

  1. Minute 0

    The incident arrives, whatever the channel

    A monitoring alert, a message from the service provider, a call from an employee, complaints or a merchant asking why its direct debits are missing: every incoming report goes into a case, and reports about the same outage are combined. The 24 hours run from the moment you first become aware.

  2. from minute 5

    Collecting the criteria while the incident is running

    The workflow keeps count: merchants and contracts affected, duration, direct debits not generated, possible data losses, countries affected, foreseeable costs. From the register of information it knows which function the system supports and whether it is listed as critical.

  3. Hours 1 to 3

    Classification with a proposal and reasons

    As soon as a threshold from your rules is reached, the workflow presents its proposal, with the values for each criterion. Your information security officer confirms or changes it. From then on, the deadline clock shows both deadlines side by side. In the example: classification at 10:30, so the initial notification is due by 14:30, long before the 24 hours end on Tuesday at 07:05.

  4. by hour 4 after classification

    Initial notification to BaFin

    The draft initial notification is produced from the case. The clock sends reminders after two and three hours and escalates to management if nobody has approved it. After approval, the notification is entered in the reporting portal; the acknowledgement of receipt goes into the log with a timestamp.

  5. in parallel

    Merchants whose payments are affected

    If direct debits fail, the incident affects your customers' financial interests. The workflow identifies from the contract system which merchants are affected and prepares the message to them. It may only go out after approval.

  6. by hour 72 after the initial notification

    Intermediate report

    The workflow gathers the service provider's findings and the status of recovery and writes the draft intermediate report.

  7. one month after the last intermediate report

    Final report from the log

    Cause, duration, customers affected, costs, measures and every point in time are already in the case. The draft is produced from them, and your people add the assessment.

  8. afterwards

    Lessons

    The lessons go into the rules: adjusted thresholds, a new template, a stricter notification deadline in the contract with the service provider.

Cascade

Who learns what has happened, and when

The supervisory authority is only one recipient among many. Each wave going out has a draft, a person who approves it and a point in time in the log; the internal alert goes out immediately.

The waves of the cascade with recipient, channel, content and approval
WaveRecipientChannelContentApproval
1, immediatelyExecutive board or management, information security officer, complianceTeams or a call, situation report from the caseWhat is down, status of the criteria, deadlines runningNone, internal alert according to a fixed list
2, deadlines of the regulationBaFinReporting portal, pre-filled from the caseInitial notification, intermediate report, final reportManagement
3, without undue delayMerchants with affected paymentsEmail or letter from the template, merchant portal, a call to large merchantsWhat has happened, what happens to the payment, contactManagement and compliance
4, ongoingICT third-party service provider and, through it, its subcontractorsEmail to the contacts named in the contractQuestions about cause, duration and data, with a deadline for answersInformation security
5, the same dayPartner banks and payment systems through which you settleEmail to the contacts on file, a call if neededFailed payment files, new dateHead of finance
6, as the situation requiresAuditors, internal audit, insurersEmail with an export from the caseCourse of events, points in time, notifications, amount of lossManagement

You set the order and the templates in the analysis. The workflow follows up when the service provider lets the contractual deadline pass or a merchant has not been reached.

Approval

What stays with your people

  • The classification. The workflow proposes and shows the values for each criterion. Whether the incident is major is decided by your information security officer, in case of doubt with compliance and the legal department.
  • Every notification to BaFin. No draft goes into the portal without approval.
  • The customer information. Wording, recipients and timing are confirmed before sending.
  • The data breach question. If personal data is affected, a notification under the GDPR may also be due. The workflow asks the question; your data protection officer answers it.
  • The conversation with the supervisor and the service provider. A person handles questions from BaFin and the negotiation with the service provider.

Integration

Which systems the workflow sits in

The reporting chain reads from the systems you have and runs on your own servers or at a service provider already listed in your register.

System integration in detail

  • IncomingMonitoring and alerts, service providers' incident notices, service inbox, merchant enquiries
  • CaseServiceNow, Jira, OTRS or the ticketing system in which your IT already logs incidents
  • RegisterRegister of information on ICT third-party service providers with functions, criticality and subcontractors, plus the contracts with their notification deadlines
  • ImpactContract system or core system with merchants and contracts, payment processing with direct debit and transfer files
  • CommunicationEmail sending with templates, merchant portal, Teams for internal escalation, the customer service team's telephone list
  • AuthorityBaFin's reporting portal. Authority portals rarely have an interface: the workflow pre-fills the notification, a person enters it, and the timestamp goes into the log.

Evidence

The log is the evidence

When the supervisor asks when you became aware, when you classified and when you reported, the answer is an export. Every step is in the case with a timestamp: first receipt, values for each criterion at classification, who approved, notifications with acknowledgement of receipt, customer information, the service provider's response times.

Auditors, internal audit and insurers receive the same export. Because the workflow also records the incidents that turned out not to be major after checking, internal audit also sees what you did not report, and why.

Twice a year, a trial run with a made-up outage passes through the entire workflow without a real notification going out. It shows whether thresholds and telephone lists are right.

Experience

What we bring

The building blocks of this reporting chain have been running at our customers for years. Reading incoming items at scale and matching them to the right case according to rules is something we know from a technology distributor with twelve sites, where enquiries from twelve sites across Europe reach the right team according to rules. Cases with log and approval run in our own operations, as does the monitoring of running workflows that reports when something has stopped.

We put the chain with its two clocks into operation with your information security and compliance teams. The acceptance test is a made-up outage at the service provider. It must show that the workflow finds the affected merchants in the contract system and that the initial notification is ready and approved within four hours of classification. We show you an example log in the first call.

Read the case studies

Price

Price and scope

The order of magnitude first: the workflow analysis costs €4,900 at a fixed price and takes three days. Based on our projects, a custom tool typically costs between €25,000 and €60,000, as a fixed price that becomes binding after the analysis; the first version is ready in about six weeks, longer with several duties and languages. Ongoing operation after that starts at €2,900 a month and can be cancelled monthly. A narrower range in advance would be guesswork: an institution with one data centre and a group with twenty service providers do not need the same tool. What determines the price:

  • number of incoming channels and monitoring systems
  • number of systems the criteria come from
  • whether the register of information is already maintained or still has to be put in order
  • whether the workflow covers only DORA or also data breaches, which often concern the same incident

Data flow: incident data, customer lists and contracts stay on your server or in a German data centre. The AI components run on open models on your own servers or via EU data centres. Data flow per service.

Related

Related use cases

Further reading: Monitoring and maintaining an AI workflow and AI data protection in companies: three ways.

Questions

Questions about the reporting chain under DORA

What management, information security and compliance want to settle before the supervisor asks for the log for the first time. More answers under Questions and answers.

Does the AI decide whether an incident is major?

No. It collects the values for each criterion, proposes a classification and gives its reasons. The decision is made by your information security officer. But the proposal comes early, as soon as a threshold is reached, so that the four hours do not only start in the afternoon and then collide with the 24 hours.

The incident is at our service provider. Who reports it?

The notification to BaFin stays with you as the financial entity. The workflow reads from the contract by when the service provider has to inform you, requests the missing details from it with a deadline and records when it answered. If you are yourself an IT service provider for financial entities, we build the same workflow for the obligations in your contracts.

Who is there at night and at the weekend, and who is liable for what?

If a system fails at night, the workflow opens the case, counts the 24 hours from becoming aware and calls the people on your on-call list until someone confirms; the classification that starts the four hours is then made by a person. As part of ongoing operation we monitor that the workflow is running, with response times on working days; round-the-clock standby is agreed separately. If it fails, the on-call list, templates and merchant list are ready as an export, and your team carries on by hand. Your institution remains responsible for the notification to BaFin; we are liable for the tool under our terms and conditions.

Doesn't the tool make us take on yet another ICT third-party service provider?

No new operator, if it runs on your own servers. We build the reporting chain on your servers or at the data centre you already list in your register of information, and the AI components can run on open models on your own servers. That way no new concentration risk arises. For your register of information we provide the details of our contract, together with an exit arrangement.

Handover

The first step is a 30-minute call.

You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.

Book a callApproach and prices